|
222491
|
5.4 |
MEDIUM
Network
|
loofah_project fedoraproject canonical debian
|
loofah fedora ubuntu_linux debian_linux
|
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15587
|
2024-11-21 13:29 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222492
|
8.8 |
HIGH
Network
|
doas_project
|
doas
|
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, primary GID, and secondary GIDs was replaced (on ce…
|
CWE-269
Improper Privilege Management
|
CVE-2019-15901
|
2024-11-21 13:29 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222493
|
9.8 |
CRITICAL
Network
|
doas_project
|
doas
|
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitial…
|
CWE-754 CWE-252 CWE-863 CWE-908
Improper Check for Unusual or Exceptional Conditions Unchecked Return Value Incorrect Authorization Use of Uninitialized Resource
|
CVE-2019-15900
|
2024-11-21 13:29 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222494
|
7.1 |
HIGH
Local
|
trendmicro
|
deep_security
|
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability impact. Local OS access is required. Please note …
|
CWE-59
Link Following
|
CVE-2019-15627
|
2024-11-21 13:29 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222495
|
7.5 |
HIGH
Network
|
trendmicro
|
deep_security
|
The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impac…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-15626
|
2024-11-21 13:29 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222496
|
8.8 |
HIGH
Network
|
eq-3
|
homematic_ccu3_firmware
|
eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can easily execute code and compromise the system.
|
CWE-862
Missing Authorization
|
CVE-2019-15850
|
2024-11-21 13:29 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222497
|
7.3 |
HIGH
Network
|
eq-3
|
homematic_ccu3_firmware
|
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the victim logs in to the session, the attacker can use that sessio…
|
CWE-384
Session Fixation
|
CVE-2019-15849
|
2024-11-21 13:29 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222498
|
4.4 |
MEDIUM
Local
|
cisco
|
telepresence_collaboration_endpoint
|
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vul…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-15962
|
2024-11-21 13:29 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222499
|
7.2 |
HIGH
Network
|
sonatype
|
nexus_repository_manager
|
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
|
NVD-CWE-noinfo
|
CVE-2019-15893
|
2024-11-21 13:29 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222500
|
7.2 |
HIGH
Network
|
mantisbt
|
mantisbt
|
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
|
CWE-78
OS Command
|
CVE-2019-15715
|
2024-11-21 13:29 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|